### Problem statement There should NEVER be any information placed in the logs, even in development unless a developer explicitly says so. ### Proposed solution - [ ] OTPs, magic-link tokens, provider tokens, refresh tokens, secret material, and private keys are redacted by default. - [ ] Development-only raw payload access requires an explicit opt-in. - [ ] Logs and auth events use redaction helpers. - [ ] Tests catch representative accidental leakage paths. ### Alternatives considered _No response_ ### Impact area Security
Problem statement
There should NEVER be any information placed in the logs, even in development unless a developer explicitly says so.
Proposed solution
Alternatives considered
No response
Impact area
Security